# Convex Reviewer > Revisor de código Convex: comprueba seguridad, auth, validators, rendimiento y patrones en código dentro de un directorio convex/. Úsalo para revisar o auditar funciones Convex antes de publicarlas. Fuente: https://skillsagentes.com/skills/get-convex/agent-skills/convex-reviewer Markdown: https://skillsagentes.com/skills/get-convex/agent-skills/convex-reviewer.md Repositorio: https://github.com/get-convex/agent-skills Autor: get-convex Licencia: Apache-2.0 Actualizado: el mes pasado Coste de contexto: 44 tok instalada, 440 tok al activarse, 440 tok con todos los archivos del bundle Bundle: 1 archivo, 2 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add get-convex/agent-skills --skill convex-reviewer --agent claude-code # Cursor npx -y skills add get-convex/agent-skills --skill convex-reviewer --agent cursor # Codex npx -y skills add get-convex/agent-skills --skill convex-reviewer --agent codex # Gemini CLI npx -y skills add get-convex/agent-skills --skill convex-reviewer --agent gemini # Windsurf npx -y skills add get-convex/agent-skills --skill convex-reviewer --agent windsurf # Cline npx -y skills add get-convex/agent-skills --skill convex-reviewer --agent cline ``` ## Qué hace - Realiza una revisión estructurada del código Convex en un directorio convex/, en tres pasadas: seguridad, rendimiento y calidad de código - Marca anti-patrones con severidad (Critical / Important / Suggestion) - Reporta hallazgos agrupados por severidad, explicando por qué importa cada uno y sugiriendo una corrección ## Cuándo usarla - Revisar o auditar funciones Convex antes de ponerlas en producción ## Qué la activa - "Revisa el código en mi carpeta convex/ antes de hacer deploy" - "Audita estas funciones Convex por problemas de seguridad y rendimiento" - "¿Hay algún anti-patrón en mis mutations de Convex?" ## Archivos - SKILL.md — 2 KB ## SKILL.md Reproducido tal cual desde get-convex/agent-skills bajo Apache-2.0. Esta sección es el documento original y está en inglés. # Convex Code Reviewer Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion). ## Workflow 1. First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal.* not api.*. 2. Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries. 3. Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements). 4. Report findings grouped by severity; explain why each issue matters and suggest a fix. ## Rules - Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk. - Flag .filter() on DB queries as Important — it is a full table scan. - Flag Date.now() in query handlers as Important — it breaks reactivity. - Flag missing args or returns validators as Important. - Flag scheduling to api.* (not internal.*) as Important. - Always explain why a change is needed, not just what to change. ## Dónde encaja - Categoría: [Testing y QA](https://skillsagentes.com/categorias/testing-qa.md) — Flujos de testing unitario, de integración y end-to-end. - Creador: [get-convex](https://skillsagentes.com/creators/get-convex.md) — 33 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) ## Otras skills del mismo repositorio - [Convex Quickstart](https://skillsagentes.com/skills/get-convex/agent-skills/convex-quickstart.md): Levanta un template Next.js + Convex barebones a partir de una idea en una frase. - [Convex Design](https://skillsagentes.com/skills/get-convex/agent-skills/convex-design.md): Diseña y construye backends reactivos y type-safe de nivel producción en Convex: schema, queries/mutations/actions, índices, auth, storage, scheduling, multiplayer en tiempo real y workflows LLM/agentes. - [Convex Authz](https://skillsagentes.com/skills/get-convex/agent-skills/convex-authz.md): Audita y refuerza la autorización de una app Convex: impersonación por identity-from-arg, checks de ownership por documento faltantes, queries públicas que filtran datos por un id del cliente y escrituras en un contenedor ajeno. - [Convex Expert](https://skillsagentes.com/skills/get-convex/agent-skills/convex-expert.md): Especialista en el backend de Convex: código dentro de convex/ (funciones, schemas, índices, queries, mutations, actions, endpoints HTTP, cron jobs, storage, auth y componentes). - [Convex Agent](https://skillsagentes.com/skills/get-convex/agent-skills/convex-agent.md): Añade un backend de agente de IA / RAG (@convex-dev/agent) a la app Convex. --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)